First published: Tue Mar 05 2013(Updated: )
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4840 has been identified as having a critical severity due to its potential to allow remote attackers to exploit XPath injection vulnerabilities.
To remediate CVE-2012-4840, upgrade IBM Cognos Business Intelligence to version 8.4.1 IF1 or later, or any of the 10.1, 10.1.1, or 10.2 versions with their respective IF updates.
CVE-2012-4840 affects IBM Cognos Business Intelligence versions 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1.
CVE-2012-4840 enables remote attackers to conduct XPath injection attacks and call XPath extension functions.
CVE-2012-4840 allows exploitation through unspecified vectors that facilitate XPath injection.